SUPRABOTS

Privacy Policy

Last updated: August 17, 2026
This is a general-purpose draft, not a substitute for advice from a lawyer, particularly if you have users in the EU/UK (GDPR) or California (CCPA), which have specific disclosure and rights requirements this draft doesn't fully cover.

1. What we collect

DataWhy
Username (stored as you typed it) and password (hashed, never stored in plain text and not reversible even by us)Your Suprabots account login
Bot configuration (server, account nickname)To run your bots
Microsoft/Xbox Live auth tokens for connected bot accountsTo keep bots signed in; we never see or store your Microsoft password
Scan history (players, mobs, blocks your bots have seen)The scan map / scan history features
Stripe customer & subscription IDs, plan tier, billing statusTo know what plan you're on. We never see or store your card number; Stripe handles that entirely

We don't currently collect your email address, phone number, or physical address for a basic account.

What "hashed" means. When you set a password, we don't save the password itself. We run it through a one-way function (scrypt) and save only the scrambled result, along with a random value unique to your account called a "salt". The process only works in one direction: the same password always produces the same result, but there is no way to work backwards from the stored result to your original password. Not by us, and not by anyone who obtained a copy of our database. When you sign in, we scramble what you typed and compare it to the stored result; if they match, the password was correct.

This is different from encryption, which is designed to be reversible by whoever holds the key. Passwords should never be reversible, which is why we hash them instead. The practical consequence for you: we genuinely cannot tell you what your password is if you forget it, because we don't know it. The salt matters too: it means two people who happen to choose the same password still get completely different stored values, so cracking one account's password tells an attacker nothing about any other account.

2. Cookies

We use one cookie: a session token that keeps you logged in. It's required for the dashboard to work and isn't used for advertising or tracking across other sites.

3. Who we share data with

We share billing-relevant information (which plan you're on, your Stripe customer ID) with Stripe to process payments; see their own privacy policy for how they handle your card details. We don't sell your data, and we don't share it with anyone else except where required by law.

4. How long we keep it

We keep your account data for as long as your account exists. If you delete your account, we delete your bot configuration, scan history, and login credentials; billing history may be retained separately by Stripe as required for their own tax/accounting obligations.

5. Your choices

You can review and delete your bot accounts and scan history from the dashboard at any time. To delete your account entirely or request a copy of your data, contact us the same way you'd reach out for support.

6. Children's privacy

Suprabots isn't intended for anyone under 13, and we don't knowingly collect data from children under that age.

7. Changes to this policy

We may update this policy as the product changes. Material changes will be reflected here with an updated date at the top of this page.

8. Contact

Questions about this policy can be sent through the dashboard's support contact, once one exists. For now, reach out however you'd normally contact us.